CVE-2025-41659
BaseFortify
Publication date: 2025-08-04
Last updated on: 2025-08-04
Assigner: CERT VDE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| codesys | control_runtime | 3.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability allows a low-privileged attacker to remotely access the PKI folder of the CODESYS Control runtime system. Through this access, the attacker can read and write certificates and their keys, enabling them to extract sensitive data or manipulate which certificates are trusted. While all services remain operational, if certificates are deleted, only unencrypted communication is possible.
How can this vulnerability impact me? :
The vulnerability can lead to sensitive data being extracted by an attacker or unauthorized acceptance of certificates as trusted, potentially allowing malicious communication to be accepted. Additionally, if certificates are deleted, communication will be unencrypted, increasing the risk of data interception or tampering.